Summary
Security Operations Center Technical LeadLocation: Colorado Springs, CO Clearance: TS/SCI with the ability to obtain and maintain a CI polygraphResponsibilities:Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOCLead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertainPerform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidenceEstablish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practicesServe as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activitiesLead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gapsApply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operationsEstablish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber riskLead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of actionCoordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as requiredPartner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilitiesIdentify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security postureLead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actionsProvide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvementsRequirements:Bachelor's degree in a relevant discipline; four additional years of relevant experience may be substituted in lieu of a degreeMinimum 8 years of directly related cybersecurity experienceMust possess a DoD 8570 IAT Level II or IAM Level II certificationExperience supporting DoD or Intelligence Community environments is desiredExpert-level, hands-on experience in SOC operations, cyber defense analysis, incident investigation, incident response, threat hunting, adversary analysis, or closely related cybersecurity operationsDemonstrated ability to establish or materially improve SOC operating procedures, investigative standards, threat-hunting methodologies, incident workflows, or analyst qualification/training programsExpert knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, adversary TTPs, threat intelligence, vulnerability/exposure management, and threat-informed defenseStrong knowledge of MITRE ATT&CK and experience operationalizing threat intelligence in SOC, threat-hunting, or cyber defense activitiesDemonstrated experience correlating vulnerability, asset, configuration, threat, incident, and security-control data to assess operational risk and prioritize remediation or defensive actionsExperience with SIEM/SOAR, detection engineering, network-security monitoring, endpoint security, vulnerability management, asset discovery, and continuous monitoring capabilitiesExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desiredExperience helping establish, transform, or mature a SOC, CSIRT, threat-hunting, or cyber defense capability is highly desiredTS/SCI with the ability to obtain and maintain a CI polygraphEqual Opportunity Employer/Veteran/Disabled group id: 90789821
Job Description
Security Operations Center Technical LeadLocation: Colorado Springs, CO Clearance: TS/SCI with the ability to obtain and maintain a CI polygraphResponsibilities:Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOCLead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertainPerform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidenceEstablish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practicesServe as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activitiesLead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gapsApply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operationsEstablish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber riskLead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of actionCoordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as requiredPartner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilitiesIdentify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security postureLead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actionsProvide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvementsRequirements:Bachelor's degree in a relevant discipline; four additional years of relevant experience may be substituted in lieu of a degreeMinimum 8 years of directly related cybersecurity experienceMust possess a DoD 8570 IAT Level II or IAM Level II certificationExperience supporting DoD or Intelligence Community environments is desiredExpert-level, hands-on experience in SOC operations, cyber defense analysis, incident investigation, incident response, threat hunting, adversary analysis, or closely related cybersecurity operationsDemonstrated ability to establish or materially improve SOC operating procedures, investigative standards, threat-hunting methodologies, incident workflows, or analyst qualification/training programsExpert knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, adversary TTPs, threat intelligence, vulnerability/exposure management, and threat-informed defenseStrong knowledge of MITRE ATT&CK and experience operationalizing threat intelligence in SOC, threat-hunting, or cyber defense activitiesDemonstrated experience correlating vulnerability, asset, configuration, threat, incident, and security-control data to assess operational risk and prioritize remediation or defensive actionsExperience with SIEM/SOAR, detection engineering, network-security monitoring, endpoint security, vulnerability management, asset discovery, and continuous monitoring capabilitiesExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desiredExperience helping establish, transform, or mature a SOC, CSIRT, threat-hunting, or cyber defense capability is highly desiredTS/SCI with the ability to obtain and maintain a CI polygraphEqual Opportunity Employer/Veteran/Disabled group id: 90789821
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Corrections Peer Recovery Specialist - Non-Merit
- Baltimore, Maryland
- GovernmentJobs.com
- Sep 02, 2026
-
Security Guard (FT or PT)
- Santa Monica, California
- Guardian National Security
- Sep 02, 2026
-
CDOC Correctional Officer I - Buena Vista
- Buena Vista, Colorado
- GovernmentJobs.com
- Sep 02, 2026
-
Patrol Officer: Protect Life, Enforce Laws, Serve Community
- Monroe, Ohio
- City of Monroe
- Sep 02, 2026
-
Truck Gate Security Officer
- Santa Monica, California
- ANDY FRAIN SERVICES
- Sep 02, 2026
-
Service Dispatcher
- Springdale, Arkansas
- Paschal Air, Plumbing & Electric
- Sep 02, 2026